Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through users.deactivateIdle to keep using already-issued login tokens. A user that an administrator has marked inactive for idleness can still access authenticated REST endpoints with the old token. This vulnerability is fixed in 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.
CVSS
No CVSS.
References
Configurations
No configuration.
History
25 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-6g3w-vg5p-w892 - |
24 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-24 21:16
Updated : 2026-06-25 16:16
NVD link : CVE-2026-45757
Mitre link : CVE-2026-45757
CVE.ORG link : CVE-2026-45757
JSON object : View
Products Affected
No product.
CWE
CWE-613
Insufficient Session Expiration
